Non-Invasive Capture Nodes for Legacy Event Harvesting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Complex Event Processing (CEP) systems face challenges in harvesting simple events from legacy systems without requiring significant modifications, which poses risks and security concerns, as they often assume easy exposure of events for monitoring.

Innovation Solution

The system employs configurable capture node modules that can operate in non-invasive modes, such as packet sniffers or log file sniffers, allowing deployment without impacting the legacy system, and includes a heartbeat mechanism for reliability, with dynamic reconfiguration capabilities to minimize invasive interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If invasive capture node modules are used to harvest simple events from legacy systems, then the ability to detect complex events is improved, but the risk of adverse behavior changes and security risks increases

Engineering Contradiction:
Improveevent detection capabilityVSAvoidsecurity risks and adverse behavior changes
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces capture node modules as intermediary components that sit between the monitoring system and legacy systems. These capture nodes harvest simple events from legacy systems without requiring the legacy systems to be directly modified or exposed to the monitoring system, thus enabling event detection while maintaining security isolation and preventing adverse behavior changes in the legacy systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The monitoring system is segmented into distributed capture node modules that can be deployed independently on or near legacy systems. This segmentation allows the system to harvest events from multiple legacy systems without requiring centralized access or modification, reducing security risks while maintaining detection capabilities.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If modifications are made to legacy systems to expose events for monitoring, then the ability to harvest simple events is improved, but the system complexity and deployment difficulty increase

Engineering Contradiction:
Improveevent harvesting capabilityVSAvoiddeployment complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The capture node modules serve as intermediaries that can be deployed on legacy systems without requiring modifications to the legacy systems themselves. The capture nodes harvest events from legacy systems through non-invasive means such as packet sniffing or log file analysis, eliminating the need to modify legacy system code or configuration while still enabling comprehensive event harvesting.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The capture node modules create copies of event data from legacy systems rather than requiring direct integration or modification. By copying events from legacy systems through non-invasive methods, the system enables event harvesting without altering the legacy systems, thus reducing deployment complexity.

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If non-invasive capture node modules are used, then the ease of deployment is improved, but the quantity of harvestable simple events may be reduced

Engineering Contradiction:
Improvedeployment easeVSAvoidquantity of simple events
Core Design Contradiction:
Ease of manufactureVSQuantity of substance

Solution Approach 1:

The capture node modules are designed with multi-functionality to harvest events from multiple sources and in multiple formats. They can capture events through various non-invasive methods including packet sniffing, log file analysis, and interface with event sources that already expose events. This universality ensures that a sufficient quantity of simple events can be harvested from diverse legacy systems without requiring invasive modifications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2553580B1Complex event processing system and method
Publication Date: 2021.07.07 BRITISH TELECOM PLC
  • EP2553580B1 patent drawingFigure 1
  • EP2553580B1 patent drawingFigure 2
  • EP2553580B1 patent drawingFigure 3

AI summary

A complex event processing system comprises a complex event processing engine (52) and an event harvesting system, wherein the event harvesting system is operable to monitor a computer network (10, 21, 22, 31, 32, 33), generate simple event reports in response to the result of monitoring the network and pass these to the complex event processing engine for processing. The event harvesting system comprises a central configuration control module (51, 53) and a plurality of capture node modules (41, 42) each of which is operatively connected to the central configuration control module. Each capture node module is operable to receive configuration instructions from the central configuration control module to determine what simple event reports are to be generated by the module and in response to what conditions detected on the monitored computer network. The central configuration control module includes an interface (51 ) in the form of a web server for receiving configuration instructions from a user of the system and for processing these configuration instructions and sending them to a specified capture node module for causing the module to operate in accordance with the specified configuration instructions.